Ȩ / ȸ»ç¼Ò°³ / ³Ê³ª¿ì¸® ¼Ò½Ä / °øÁö»çÇ×
±Ûº¸±â
ÀÛ¼ºÀÚ ³Ê³ª¿ì¸®
ÀÛ¼ºÀÏÀÚ 2014-07-23
Á¦¸ñ [°øÁö] ¸®´ª½º µµ¸ÞÀγ×ÀÓ¼­¹ö(DNS) º¸¾È À̽´ °øÁö
³»¿ë ¾È³çÇϼ¼¿ä.

ÁÁÀºÀÎÅͳÝ(ÁÖ) ÅëÅ«¾ÆÀÌ IDC ÀÔ´Ï´Ù.

ÃÖ±Ù À̽´°¡µÇ°í ÀÖ´Â ¸®´ª½º µµ¸ÞÀγ×ÀÓ¼­¹ö(DNS) º¸¾È Ãë¾àÁ¡¿¡ ´ëÇÏ¿© ¾È³» µå¸³´Ï´Ù.

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
À̸§ : DNS ÁõÆø DDOS °ø°Ý (DNS amplification DDOS attack)

  -  Ãë¾àÁ¡ Á¤º¸ : DNSÄõ¸®¸¦ ÀÌ¿ëÇÏ¿© º¹¼öÀÇ DNSÁ¤º¸ÀÀ´äÀ»
                        ¿äûÇØ °ø°ÝÆ®·¡ÇÈÀ» Áõº¹½ÃŲ ÈÄ °ø°Ý¸ñÀûÁö¸¦
                        °ø°ÝÇÏ´Â ¼­ºñ½º¹æÇØ °ø°Ý±â¹ý

  -  °ø°Ý DNSÄõ¸® ³»¿ë : UDP ÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇÏ¿© ƯÁ¤ ³×Æ®¿öÅ©
                                  ´ë¿ªÀüüÀÇ DNS ¼­¹ö¿¡ ºÒƯÁ¤ µµ¸ÞÀο¡
                                  ´ëÇÑ Á¤º¸¸¦ µµ¸ÞÀγ×ÀÓ¼­¹ö(DNS)¿¡ ¿äû

  -  ´ëÀÀ¹æ¾È :
          1. DNS¼­¹ö¿¡ ¾ø´Â Á¤º¸´Â ÀÀ´äÇÏÁö ¾Êµµ·Ï ¼³Á¤
             ->  /etc/named.conf¸¦ option ¿µ¿ª recursion no; ¸¦ Ãß°¡ÇÏ°í
                  localhost ¿µ¿ª¿¡ recursion no;·Î ¿É¼ÇÀ» º¯°æ
          2. DNS¼­¹ö¿¡¼­ bind µ¥¸óÀ» »èÁ¦ÇÏ°í ´Ù¸¥ ³×ÀÓ¼­¹ö·Î
              ÀÌÀüÀ» ÁøÇà
             ->  Âü°íÆäÀÌÁö
                  (https://www.tongkni.co.kr/idcplus/plugin/dnsservice.asp)
          3. iptables º¸¾È °­È­¼³Á¤
             ->  ÇØ´ç °ø°Ý¿¡ ´ëÇÑ °¨½Ã»çÀÌÆ®
                  (http://dnsamplificationattacks.blogspot.kr)
                  ÂüÁ¶ÇÏ¿© /etc/sysconfig/iptables¿¡ Á¤º¸¸¦  IPÁ¤º¸¸¦ Ãß°¡
                  º¸¿ÏÇÕ´Ï´Ù.

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

ÀÌ»óÀÔ´Ï´Ù.
  Ȩ ¤Ó ȸ»ç¼Ò°³ ¤Ó °³ÀÎÁ¤º¸Ã³¸®¹æħ ¤Ó ¼­ºñ½ºÀÌ¿ë¾à°ü